[SECURITY] Bug 209742: Under some circumstances, a user can obtain component descriptions for a product to which he does not normally have access.

Patch by Ryan Cleary <tryanc@interdimensions.com>
r= joel, bbaetz   a= justdave
This commit is contained in:
justdave%syndicomm.com 2003-11-03 03:25:51 +00:00
Родитель fe70c2e6d7
Коммит d2043e034b
1 изменённых файлов: 1 добавлений и 1 удалений

Просмотреть файл

@ -46,7 +46,7 @@ if (!defined $::FORM{'product'}) {
# Reference to a subset of %::proddesc, which the user is allowed to see
my %products;
if (AnyDefaultGroups()) {
if (AnyEntryGroups()) {
# OK, now only add products the user can see
confirm_login() unless $::userid;
foreach my $p (@::legal_product) {